AtomSilo is a double-extortion ransomware group that emerged in September 2021, exploiting the Atlassian Confluence vulnerability (CVE-2021-26084) for initial access and demanding ransoms up to $1 million, attributed to the Chinese state-linked threat actor BRONZE STARLIGHT. Known victims: 5 1 ransom note(s) on file
Objectives
Executive Summary
AtomSilo is a medium-sophistication criminal threat actor specializing in ransomware operations with a primary focus on financial gain. Known for double-extortion tactics, AtomSilo uses initial access via the Atlassian Confluence vulnerability (CVE-2021-26084) and has targeted sectors such as healthcare and education. The group is suspected to be linked to BRONZE STARLIGHT, a Chinese state-linked actor, and has been active since December 2021.
Goals & Targeting
AtomSilo targets sectors with sensitive data or less robust cybersecurity defenses, such as healthcare and education. The group seeks to maximize financial gains through double extortion campaigns, where victims are coerced into paying ransoms or face public shaming via leaked data. Their strategic focus appears to be on disrupting organizational operations while leveraging high-profile attacks to establish notoriety in the ransomware landscape. Typical victims include mid-to-large sized organizations with accessible network entry points.
Enhanced Description
AtomSilo is a double-extortion ransomware group that emerged in late 2021, leveraging the Atlassian Confluence vulnerability (CVE-2021-26084) for initial network access. The group operates with a clear focus on financial gain, employing double extortion tactics where victims are threatened with data leaks if they fail to pay the ransom. AtomSilo's targeting patterns suggest a preference for sectors like healthcare and education, possibly due to their access to sensitive data or weaker defensive postures. The group has been linked to BRONZE STARLIGHT, a Chinese state-linked threat actor, further complicating its operational landscape. Known victims include organizations in North America and Europe, with one notable incident involving the deployment of high ransom demands (up to $1 million). AtomSilo's campaign patterns indicate a focus on disrupting operations while maximizing financial gain through sophisticated extortion schemes.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
AtomSilo's campaigns typically involve phishing emails, exploitation of CVE-2021-26084, and deployment of ransomware with double extortion demands. The group appears to target organizations in the healthcare and education sectors, as seen in a notable attack on a US healthcare system in June 2022. Campaigns often include threats of data leaks to pressure victims into payment. Notable operations include high-profile attacks on educational institutions and healthcare providers, with a focus on maximizing financial gain through large ransom demands.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in AtomSilo's profile, with additional context needed on specific tools and exact targeting criteria. Further analysis of campaign TTPs and technical indicators is required to fully understand the group's capabilities.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics